PT-2025-36263 · Linux+3 · Linux Kernel+3

Published

2025-08-07

·

Updated

2026-04-07

·

CVE-2025-38733

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to memory management on s390 systems. The lowcore region was incorrectly mapped with the identity mapping, potentially leading to successful NULL pointer accesses instead of expected exceptions. This occurred regardless of the relocate lowcore command line option, and in cases where the option was specified, the lowcore was mapped twice. The issue was addressed by preventing the mapping of the first two pages of physical memory with the identity mapping.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-15742
CVE-2025-38733
DSA-6008-1
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse